Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability with deep-defaults dependency #1675

Open
joshua-holmes opened this issue Jun 5, 2024 · 0 comments
Open

Security vulnerability with deep-defaults dependency #1675

joshua-holmes opened this issue Jun 5, 2024 · 0 comments

Comments

@joshua-holmes
Copy link

Hello, there is a CVE open for a security vulnerability in deep-defaults up to and including v1.0.5, which is the latest version. The deep-defaults npm page states that the project is deprecated and shows a message from the author, "not actively maintained; find alternatives." Since deep-defaults is no longer maintained and has a security vulnerability, it should be swapped out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant